Database/Kernel, userspace & hypervisor
Linux kernel (drivers/gpu/drm/xe): A GPU TLB invalidation for a very large address range computes its length with a
Impact
A GPU TLB invalidation for a very large address range computes its length with a power-of-two roundup that overflows, producing an undefined shift and a bogus invalidation length. The operator-level consequence is that GPU TLB entries for pages the kernel believes it has unmapped may survive, letting a tenant's GPU keep touching host pages after they have been freed and potentially handed to another workload.
Who can reach it
Reachable from an unprivileged process in a container with /dev/dri/renderD* on an Intel Xe node with SVM/userptr in use: map a huge address range into the GPU, then tear it down (or simply exit) so the MMU notifier fires xe_svm_invalidate with a range larger than the roundup can represent. Observed in practice from a plain userspace exec test, no special privilege.
What to do
Update to a kernel with the fix commits below, which falls back to a full TLB invalidation above a size threshold. Interim: deny /dev/dri render nodes to untrusted tenants on xe hosts; there is no knob to disable SVM range invalidation.
References
Related entries
- Linux kernel (drivers/gpu/drm/xe): The error path of the Xe VRAM clear helper waits on a fence pointer that is onlyCVE-2025-37869 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): Xe frees data that its exported dma-fences still point at - notably the timelineCVE-2025-38703 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): A tenant that submits a deliberately malformed array bind to the Xe VM_BIND ioctlCVE-2025-38731 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): On the migration error path the previous fence is released before the code waits onCVE-2025-39740 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): The observation-config ioctl dereferences the config object after releasing the lockCVE-2025-71099 · Linux kernel (drivers/gpu/drm/xe)High
- Linux kernel (drivers/gpu/drm/xe): The Xe userptr path takes folio locks while holding the MMU notifier lock, whichCVE-2025-37868 · Linux kernel (drivers/gpu/drm/xe)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.